Live data from Hacker News

Project Abacus: Google's plan to kill the password via biometric tracking

engadget.com

21–30 of 59 posts

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#21
post #17

Earlier quoted context omitted.

Capable? Have you heard about prism? Google claims to have been in the dark, that data was siphoning off as it flowed between data centers. That is an admission that Google is not capable of protecting against such things. They claim to have not even contemplated the attack. To quote the boss: "Until this week’s reports, we had never heard of the broad type of order that Verizon received—an order that appears to have…

Yes, and as a result traffic is now encrypted between data centers. And I'm not sure what your quote adds to the point.

My point is that google's claims today cannot be trusted any more than when those same claims made three years ago. Google was wrong about it's abilities then as it may be wrong about them today.

Google is now so large that 'trust' is impossible. Google's attack surface is now so vast, the data so valuable, and cross-talk of personnel with government so common that the likelihood of another undetected breech is too great to ignore. (Same for apple/facebook et al).

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#22
post #2

(disclosure: I am a Googler, but I have nothing to do with this project) Passwords are problematic, easy to lose, easy to steal, but an issue with biometric identify verification is that you can no longer maintain multiple personas. Using a password with 2FA, you can quite easily maintain two sets of those credentials, assuming that the authority doesn't demand proof of real name or such nonsense. If you trust the au…

That's not really true though, if the access to both of these accounts is granted with the same credentials it does not matter whether those credentials are a password or biometric data.

The bad part is when the account disappears completely and you only have the option to use the biometric data.

So there is a middle ground.

> And, I trust Google... today.

I don't. Todays google is the google I saw coming quite a few years ago and it is as bad as I feared it would be and too large to be able to get around without losing out on valuable participation. Facebook, Microsoft and Apple are a lot easier to avoid than Google.

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#24
post #17

Earlier quoted context omitted.

Capable? Have you heard about prism? Google claims to have been in the dark, that data was siphoning off as it flowed between data centers. That is an admission that Google is not capable of protecting against such things. They claim to have not even contemplated the attack. To quote the boss: "Until this week’s reports, we had never heard of the broad type of order that Verizon received—an order that appears to have…

Yes, and as a result traffic is now encrypted between data centers. And I'm not sure what your quote adds to the point.

His point is - if I may - that if they could not foresee that this was the case in the past that there is a good reason to assume they won't be able to foresee similar things in the present.

It's not as if it took a great feat of imagination to suspect that data flowing between datacenters would be tapped.

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#26
I didn't watch the linked I/O presentation, but I clicked through to the Ars Technica article. Are there any details that suggest this would be more than just v2 of fingerprint unlock?

aka optional, local and circumventable with a password if my fingerprint isn't recognized?

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#27
post #4

The server side of major services already perform some very sophisticated probablistic authentication mechanisms. Ever had Google or facebook ask you to sign in again when you got off a flight or accessed a sensitive setting? You've experienced it firsthand. Taking it down to the device level is just acknowledging the danger of loss or stolen second factors. Further, frameworks like tensorflow may allow the learning…

I've never been prompted to reauthenticate to Facebook or Google based on travel, actually, and if I was, I would be paranoid about a MITM attack. Has this happened to anyone?

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#28
post #15

Earlier quoted context omitted.

It could be even creepier if the biometric data could be sold to third parties, or if Google were to offer an identification service for third parties.

Medical researchers?

Insurance Agents?

So, Mr. Owl, I'm afraid that your insurance premiums are going up. Why? Because of that slip on the ice two days ago; our monitoring indicates that you have injured your back. Yes, I know you haven't even seen a doctor yet, but there's a 62% probability that you will be making a large claim shortly, so up with your premiums!

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#29
post #20

> And then we have fingerprints, which are very secure and onerous to imitate Aaaaand there goes the article's credibility. A pity, because there's a real need for a cogent debate about this panopticon-as-password program.

The best thing about fingerprint authentication is that you can (literally) hack up a way for up to ten people to share a device.

Re: Project Abacus: Google's plan to kill the password via biometric tracking

#30
> Cisco engineer Shawn Cooley countered him saying, "very cool until I break my leg or hand & can't auth to any services to get healthcare info since my behavior is diff." Messina said, "you presume that your health records aren't being managed by Verily. You would be wrong."

So Verily would be automatically sharing information with Abacus to modulate its user identification, and they feel can just start doing that because it's also an Alphabet company.

This sets off alarm bells in my head. Is this the attitude toward privacy and data isolation at Alphabet/Google? How long until these health records are also shared with Google's advertising department? It tells me that they have no business managing health records at all.

Post reply on HN